CVE-2024-54747

WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wavlink:wn531p3_firmware:202383:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn531p3:-:*:*:*:*:*:*:*

History

03 Oct 2025, 00:51

Type Values Removed Values Added
CPE cpe:2.3:h:wavlink:wn531p3:-:*:*:*:*:*:*:*
cpe:2.3:o:wavlink:wn531p3_firmware:202383:*:*:*:*:*:*:*
First Time Wavlink wn531p3 Firmware
Wavlink wn531p3
Wavlink
References () https://colorful-meadow-5b9.notion.site/WN531P3_HardCode_vuln-14ac216a1c30805c9b4dd59028d866cc?pvs=73 - () https://colorful-meadow-5b9.notion.site/WN531P3_HardCode_vuln-14ac216a1c30805c9b4dd59028d866cc?pvs=73 - Exploit, Third Party Advisory
References () https://docs.wavlink.xyz/Firmware_ch/fm-531p3/ - () https://docs.wavlink.xyz/Firmware_ch/fm-531p3/ - Product

09 Dec 2024, 15:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió que WAVLINK WN531P3 202383 contiene una vulnerabilidad de contraseña codificada en /etc/shadow, que permite a los atacantes iniciar sesión como superusuario.
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

06 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-06 16:15

Updated : 2025-10-03 00:51


NVD link : CVE-2024-54747

Mitre link : CVE-2024-54747

CVE.ORG link : CVE-2024-54747


JSON object : View

Products Affected

wavlink

  • wn531p3
  • wn531p3_firmware
CWE
CWE-276

Incorrect Default Permissions